Summary
Migrate GraphForge npm publication from long-lived NPM_TOKEN (Bypass 2FA) to npm trusted publishing (GitHub Actions OIDC) with provenance attestations, matching PyPI and crates.io.
Acceptance criteria (in-repo)
Human console steps (before first OIDC npm publish)
On npmjs.com, configure a GitHub Actions trusted publisher for each of the 8 @curatelabs packages:
@curatelabs/graphforge-darwin-arm64
@curatelabs/graphforge-darwin-x64
@curatelabs/graphforge-linux-arm64-gnu
@curatelabs/graphforge-linux-x64-gnu
@curatelabs/graphforge-win32-x64-msvc
@curatelabs/graphforge
@curatelabs/graphforge-cli
@curatelabs/graphforge-agent-skills
For each package → Package Settings → Trusted Publisher → GitHub Actions:
- Owner:
CurateLabs
- Repository:
graphforge
- Workflow filename:
publish.yaml
- Environment: leave blank (same as PyPI)
Also confirm the @curatelabs org allows OIDC trusted publishing. For any package that does not yet exist, use npm’s pending trusted-publisher / first-publish flow.
Retire NPM_TOKEN
Only after a successful publish.yaml npm lane authenticates via OIDC:
gh secret delete NPM_TOKEN --repo CurateLabs/graphforge
Rotate any local copies of the former granular Bypass-2FA token.
Out of scope
- Binding RC Bazel cutover
publish.yaml concurrency / environment keys / stale tag defaults
- Changing publish-once / attempt-receipt semantics
References
- Devinfra Audit priority: npm trusted publishing + provenance
Summary
Migrate GraphForge npm publication from long-lived
NPM_TOKEN(Bypass 2FA) to npm trusted publishing (GitHub Actions OIDC) with provenance attestations, matching PyPI and crates.io.Acceptance criteria (in-repo)
publish.yamlnpm jobs haveid-token: writeand do not projectNPM_TOKEN/NODE_AUTH_TOKENscripts/publish_npm_artifacts.pypublishes with--provenanceand routes--packagethrough integrity-resume (publish_one)release-credential-preflight.ymland contract tests assert the OIDC / no-token modelpublication-order.md,RELEASING.md, v0.5 runbook) drop Bypass-2FA /NPM_TOKENrequirements and document npm trusted publishing like PyPI/cratesHuman console steps (before first OIDC npm publish)
On npmjs.com, configure a GitHub Actions trusted publisher for each of the 8
@curatelabspackages:@curatelabs/graphforge-darwin-arm64@curatelabs/graphforge-darwin-x64@curatelabs/graphforge-linux-arm64-gnu@curatelabs/graphforge-linux-x64-gnu@curatelabs/graphforge-win32-x64-msvc@curatelabs/graphforge@curatelabs/graphforge-cli@curatelabs/graphforge-agent-skillsFor each package → Package Settings → Trusted Publisher → GitHub Actions:
CurateLabsgraphforgepublish.yamlAlso confirm the
@curatelabsorg allows OIDC trusted publishing. For any package that does not yet exist, use npm’s pending trusted-publisher / first-publish flow.Retire
NPM_TOKENOnly after a successful
publish.yamlnpm lane authenticates via OIDC:Rotate any local copies of the former granular Bypass-2FA token.
Out of scope
publish.yamlconcurrency / environment keys / stale tag defaultsReferences